Re: A more fundamental issue..
Marius Huse Jacobsen <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Hello Jeroen,
Wednesday, November 5, 2003, 3:20:33 PM, you wrote:
JvD> As computing become ever more powerful and oop scripting languages ever more
JvD> prevalent and simple, more and more programmers will know less about OS &
JvD> library component fundamentals. As computing becomes ever more pervasive,
JvD> the security of code in the OS & library components will over the years only
JvD> become more important while becoming the domain of an ever more exclusive
JvD> club (because their members are mainly highly experienced C/C++ programmers).
So, if things don't change direction, you fear that the entire
industry (or would you say the entire world?) will depend on a few
'gurus' to maintain the link between the low-level and the high-level
in a secure fashion?
<snip>
JvD> This century will most likely see advanced,
JvD> intimate human interface technologies introduced, and once they are available
JvD> their benefits will most likely mandate their use.
Let me add one line to this:
For those that can afford it.
JvD> And so we program in ever higher scripting abstractions, we interface ever
JvD> closer to and into our skins and minds, we integrate systems ever closer to
JvD> rely on and reuse of each other. All this is built on increasingly complex
JvD> layers in the OS and in library toolkits.
And the fewer that understands the 'connectors' between high-level and
low-level parts of the system, the bigger the potential problems, is
that what you're saying?
Reuse will also reuse the bugs?
A system that depends on a faulty system is a system that could fail
any moment?
<moved>
JvD> These technologies will
JvD> most likely aim to wire us directly into the computer.
JvD> As computing becomes ever more pervasive, even intimate, exploits can lead to
JvD> increasing disaster.
Have you seen the anime "Ghost in the shell" ?
For those who haven't, I'll summarize the relevant parts. For most of
it, at least the beginning, there is a hunt for a "ghost hacker", one
who hacks ghosts. Ghosts being the digitized minds of people, that can
be downloaded into a host - just think of it as a human-looking robot.
In that way, you could travel around the world in the time it took to
transfer your brain data to the new 'host'.
In that anime, that ghost hacker replaced memories, among other things
- not something that I'd expect we'll see until we have a full
conversion wetware->software happening. In the setting, this had
already happened.
I'm not going to say much more, as that could spoil the fun for those
who have yet to see it.
The problem is, under the conditions in the setting of the anime, it
is a realistic scenario. Until the wetware to software conversion
happens though, I can think of a few ventures...
First of all, a specific part of the entertainment industry would love
the ability to introduce specific arbitrary feelings to your nerves.
Secondly, there's the opposite. For interrogation or any other
purpose, it would be a good tool for torture. Feeling safe already?
For that sort of reason, you'd have to make sure security really kept
up, and with todays standard for computer security... it's perhaps
better left unsaid.
JvD> Our mode of thinking about security may have kept up to date with the
JvD> requirements but isn't yet really taking the foreseeable evolution and
JvD> convergence of computing and other sciences into account. Computing security
JvD> is becoming a political concern but that concern is still too shallow and
JvD> mainly has to do with issues such as 'bundling', 'sharing' and 'digital
JvD> rights'.
Instead of? Accountability?
JvD> The OS and library components are becoming open, public
JvD> infrastructure but the trend is at risk from the current political focus on
JvD> private instead of public ownership protection.
JvD> Security socially is about accountability and transparency. Programmers and
JvD> the politicians now are setting the mold for other sciences to follow.
JvD> Especially the science of genetic and bioengineering requires a much more
JvD> accountable mold before its products can become as ubiquitous as our
JvD> handywork.
I'm shuddering at the thought of those sciences having the same
standard of security as computer software. ("as is")
I think microsoft would be in big trouble if they could be held
accountable for the security problems in their software.
JvD> If we are to see the same lack of security professionalism and a
JvD> similar level of expediency in bioindustries as we see in the software
JvD> industry we have a lot more to fear from vulnerabilities and exploits and
JvD> lack of patches there. Hopefully in the nearby future we have enough OS &
JvD> library knowhow of our own internals so that we can patch something like Sars
JvD> quickly. The need for that knowhow to be "open source" is evident otherwise
JvD> we as a species could be ransom to profiteering.
Because only those who could pay the most would get cures.
I think that part lost much of its link to computer security,
JvD> ps: I've gone through a couple of drafts, don't mean to cry wolf, but we are
JvD> on the eve of our development model spilling over into other sciences that
JvD> increasingly use computing in development and manufacturing.
Seems to me that most use computers as tools, and are luckily not
copying our software making processes. Therefore, it seems to me like
a cry of wolf. I could be wrong in my perceptions, though.
One thing about the comparison to the biotech and GenEng branches, is
that one can avoid computer software vulnerabilities completely - by
ditching computers totally. You can hardly avoid biotech when their
wee ones come to get you!
JvD> It's a fairly
JvD> alarming trend considering that we as a society seem to spend more media time
JvD> on security issues within our computers than in our biosphere.
Is that so? Well, seems to me that there is more knowledge around
about it too - both what we know the most about, and what 'people in
general' knows. It's a lot more 'absolute' when applying the word to
the knowledge (as opposed to the effects). Therefore, it's less
obscure, and so it is more interesting.
Mass media spends time on what's interesting, not what's important.
Successful media either targets a specific (small) selection of
people, or covers things that are interesting instead of obscure.
JvD> It's also
JvD> alarming that after so much public scrutiny and debate we are still on the
JvD> religious discourse of good and evil.
So that discussion is alive and kicking still?
I thought they had finally come to the conclusion that good and evil
could not be defined long ago.
--
Best regards,
Marius mailto:[email protected]
--
They hunt the 'malicious' hackers,
leaving those who greedily earn lots
of money on faulty products alone.